SECURITY Signal 56
Equifax automates half of its security tickets with AI
Equifax uses AI to handle half of its SOC tickets, cutting code-security review time from 46 days to 18 days and adding controls for autonomous agents.
By automating half of security tickets, Equifax reduces analyst workload and accelerates vulnerability response. The faster code-security reviews shorten remediation cycles, helping the company keep pace with automated attack timelines. Adding identity-based controls for AI agents aims to prevent misuse while retaining human verification for critical actions.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
AI now processes 50% of SOC incident tickets, handling 19.8 million alerts per day.
Code-security review duration dropped from 46 to 18 days, with AI generating fixes for over 213,000 findings yearly.
Equifax applies strict identity and network controls to AI agents, requiring human approval for high-risk actions and monitoring for drift.
THE READ
What the cluster adds up to.
Equifax reports that its AI systems now handle half of the security operations center incident tickets, processing about 19.8 million alerts each day. The same AI agents analyze container vulnerabilities and automatically generate code fixes, reducing the average code-security review from 46 days to 18 days. This acceleration allows human analysts to focus on the most critical cases while still verifying automated remediation. The company says the change follows years of post-2017 breach remediation and responds to a 30% rise in attack volume driven by automation.
To keep AI agents from becoming uncontrolled, Equifax treats them as privileged production identities, applying identity-based access controls and network boundaries that limit each agent to the resources it needs. New agents must pass policy-as-code testing before deployment, and high-risk actions require explicit human approval. Continuous monitoring for drift or unpredictable behavior is paired with automated kill switches and instant rollback capabilities. These controls add policy, testing, and approval overhead around every automated capability.
While the automation speeds up ticket triage and code review, the reported metrics are internal measurements without independent benchmarks or published error rates for the AI-generated fixes. Consequently, the figures demonstrate deployment scale but do not directly prove improved security effectiveness. The reliance on human verification for consequential decisions means that full autonomy is not achieved, and any gaps in agent oversight could still expose the organization to risk. Equifax’s approach shows that scaling AI in security requires balancing speed with strict governance and ongoing human oversight.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗